Autors: Rusev, A. N., Sharabov, M. Z., Tsochev, G. R., Trifonov, R. I.
Title: Artificial intelligence methods suitable for lateral movement detection
Keywords: Artificial intelligence, lateral movement, rdp

Abstract: The COVID-19 pandemic forced many companies to send their employees to work from home, which led to a significant increase in cyberattacks over RDP. Remote Desktop Protocol (RDP) is a Microsoft protocol that allows administrators to access desktop computers remotely. As it gives the user full control over the device, it is a valuable entry point for adversaries. Every cyberattack goes through several stages before its termination. Lateral Movement is one of those stages that is of particular importance. This article presents the first step of a project for Designing a remote connection protection system based on artificial intelligence methods. The research reviews the problems in lateral movement detection. A literature review is conducted, outlining techniques for automatic detection of malicious lateral movements. There is a discussion about the possibility of using artificial intelligence methods in lateral movement detection and the choice of an appropriate method.

References

    Issue

    Proceedings of the 48th International Conference “Applications of Mathematics in Engineering and Economics”, 2023, Bulgaria, AIP conference proceedings, https://doi.org/10.1063/5.0178853

    Вид: пленарен доклад в международен форум, публикация в издание с импакт фактор, публикация в реферирано издание, индексирана в Scopus и Web of Science